Privacy Policy

This Privacy Policy describes how Costa Vida ("we," "us," "our," or "the Company") collects, uses, discloses, retains, and protects your personal information when you visit our website at vida-costas.world, place orders, use our services, or otherwise interact with us. We are committed to protecting your privacy and handling your personal data with transparency, integrity, and in full compliance with applicable United States privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Federal Trade Commission Act (FTC Act).

Please read this Privacy Policy carefully. By accessing or using our website, placing an order, or otherwise engaging with Costa Vida, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree with any part of this policy, please discontinue use of our services immediately.

If you have any questions or concerns regarding this Privacy Policy, you may contact us at any time using the contact details provided in the Contact Us section below.


1. About Costa Vida

Costa Vida is a food service business operating in the United States, dedicated to providing customers with fresh, high-quality food and a memorable dining experience. Our digital presence, including our website at vida-costas.world, allows customers to browse our menu, place online orders, learn about promotions, and connect with us.


2. Scope of This Privacy Policy

This Privacy Policy applies to all personal information collected by Costa Vida through the following channels:

  • Our website at vida-costas.world and any related subdomains
  • Online ordering systems and digital platforms operated by or on behalf of Costa Vida
  • Email, telephone, or other electronic communications between you and Costa Vida
  • In-store data collection where applicable (e.g., loyalty program sign-ups)
  • Social media platforms and third-party services where Costa Vida maintains a presence
  • Marketing campaigns, surveys, and promotional activities

This policy does not apply to third-party websites, services, or applications that may be linked from our website. We encourage you to review the privacy policies of any third-party platforms you visit independently.


3. Information We Collect

We collect various categories of personal information depending on how you interact with us. The categories below describe the types of data we may gather:

3.1 Personal Identification Information

When you create an account, place an order, or contact us, we may collect:

  • Full name
  • Email address
  • Phone number
  • Billing and delivery address (including street, city, state, ZIP code)
  • Date of birth (where required for age verification or promotional purposes)
  • Username and password (for account holders)
  • Profile photograph (if voluntarily uploaded)

3.2 Payment and Transaction Information

When you make a purchase through our platform, we collect transaction-related information, including:

  • Payment card type (e.g., Visa, MasterCard)
  • Last four digits of your payment card (full card numbers are processed by PCI-DSS compliant third-party payment processors and are not stored by us)
  • Order history, items purchased, and total transaction amounts
  • Gift card and coupon codes redeemed
  • Refund and dispute records

3.3 Usage Data and Interaction Information

We automatically collect certain data when you visit or interact with our website, including:

  • Pages visited, time spent on each page, and links clicked
  • Search queries entered on our website
  • Shopping cart activity and abandoned cart data
  • Referring URL (the website that directed you to ours)
  • Timestamps of visits and interactions
  • User session recordings (where applicable and disclosed)

3.4 Device and Technical Information

We automatically collect technical information from your device when you visit our website, including:

  • IP address
  • Browser type and version (e.g., Chrome, Firefox, Safari)
  • Operating system and version
  • Device type (desktop, tablet, mobile)
  • Screen resolution
  • Internet service provider
  • Geolocation data (approximate, based on IP address)
  • Unique device identifiers

3.5 Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, and similar tracking technologies to enhance your experience on our website. Please refer to Section 9 (Cookie Usage) below for detailed information about our cookie practices. By continuing to use our website, you consent to our use of cookies in accordance with this policy.

3.6 Communications and Customer Service Data

When you contact us or participate in our communications, we may collect:

  • Content of emails, messages, or calls you send to us
  • Records of customer support tickets and resolutions
  • Responses to surveys, reviews, or feedback forms
  • Social media messages and comments directed at our brand accounts

3.7 Marketing and Preference Data

Where you have opted in to receive marketing communications, we may collect:

  • Marketing preferences and subscription status
  • Communication history (e.g., emails opened, links clicked)
  • Promotional participation records (sweepstakes, contests, loyalty programs)

3.8 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Social media platforms (if you connect your account or interact with our social media pages)
  • Third-party delivery partners
  • Analytics and advertising partners
  • Fraud prevention services
  • Publicly available databases

4. How We Use Your Information

Costa Vida uses the personal information we collect for the following purposes:

4.1 Service Provision and Order Fulfillment

  • Processing and fulfilling your food orders, whether placed online or in-store
  • Managing your account and providing access to account-specific features
  • Coordinating delivery or pickup of your orders
  • Processing payments and issuing refunds where applicable
  • Sending order confirmations, receipts, and status updates

4.2 Customer Support and Communication

  • Responding to your inquiries, complaints, or feedback
  • Providing technical support for our website and online ordering system
  • Notifying you of changes to our menu, policies, or services
  • Resolving disputes and enforcing our Terms of Service

4.3 Analytics and Service Improvement

  • Analyzing website traffic, user behavior, and purchasing patterns to improve our services
  • Conducting internal research and product development
  • Monitoring and improving website performance and security
  • Generating aggregated, anonymized statistical reports
  • Testing new features and functionality

4.4 Marketing and Promotional Activities

  • Sending you promotional emails, newsletters, or special offers (where you have opted in)
  • Delivering personalized advertisements on our website and third-party platforms
  • Running loyalty programs, contests, and sweepstakes
  • Conducting customer satisfaction surveys
  • Re-targeting campaigns based on your browsing or purchasing history

4.5 Legal Compliance and Safety

  • Complying with applicable federal, state, and local laws and regulations
  • Preventing fraud, unauthorized access, and other illegal activities
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public
  • Cooperating with law enforcement and regulatory authorities when required
  • Enforcing our legal agreements and policies

5. Legal Basis for Processing

While the United States does not have a single overarching federal privacy law equivalent to the EU's GDPR, Costa Vida processes personal information based on the following recognized grounds:

  • Contractual necessity: Processing required to fulfill your order, manage your account, or deliver services you have requested.
  • Legitimate interests: Processing necessary for our legitimate business interests, such as fraud prevention, improving our services, and direct marketing (where we ensure these interests do not override your privacy rights).
  • Consent: Processing based on your explicit, freely given consent, particularly for optional marketing communications and non-essential cookies.
  • Legal obligation: Processing required to comply with applicable laws, court orders, or regulatory requirements.

6. Sharing Your Information with Third Parties

Costa Vida does not sell your personal information to third parties for monetary compensation. However, we may share your information with trusted third parties in the following circumstances:

6.1 Service Providers and Business Partners

We engage third-party companies and individuals to assist us in operating our business and delivering our services. These service providers are granted access to your personal information only to the extent necessary to perform their functions and are contractually bound to maintain confidentiality and security. Categories of service providers include:

  • Payment processors and financial institutions (for secure payment handling)
  • Cloud hosting and data storage providers
  • Food delivery and logistics partners
  • Email marketing and CRM platforms
  • Website analytics providers (e.g., Google Analytics)
  • Advertising and retargeting networks
  • Customer support software providers
  • Fraud detection and cybersecurity services

6.2 Legal Requirements and Enforcement

We may disclose your personal information if required to do so by law or in the good-faith belief that such action is necessary to:

  • Comply with a legal obligation, subpoena, court order, or governmental request
  • Enforce our Terms of Service or other agreements
  • Investigate potential violations of applicable laws or our policies
  • Protect the rights, property, or safety of Costa Vida, our users, or the public
  • Respond to emergency situations involving risk to life or physical safety

6.3 Business Transfers

In the event that Costa Vida undergoes a merger, acquisition, corporate restructuring, bankruptcy, or sale of all or a portion of its assets, your personal information may be transferred to the acquiring entity or successor business. We will notify you of any such change through our website or by email, and any acquiring party will be required to honor the commitments made in this Privacy Policy.

6.4 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, or business development purposes. This data is not subject to the same protections as personal information under this policy.

6.5 With Your Consent

We may share your information with additional third parties where we have obtained your explicit consent to do so, such as in connection with co-branded promotions or partner loyalty programs.


7. Data Security

Costa Vida takes the security of your personal information seriously and implements a range of technical, organizational, and administrative safeguards to protect it from unauthorized access, disclosure, alteration, or destruction. Our security measures include, but are not limited to:

  • Encryption: We use industry-standard SSL/TLS encryption to protect data transmitted between your browser and our website. Sensitive data, including payment information, is encrypted both in transit and at rest.
  • Access Controls: Access to personal data is restricted to authorized personnel who have a legitimate business need to access it. All employees with data access are subject to confidentiality obligations.
  • Payment Security: We comply with Payment Card Industry Data Security Standards (PCI-DSS) and do not store full credit card numbers on our servers. Payment processing is handled by certified third-party processors.
  • Regular Security Audits: We conduct periodic security assessments, vulnerability scans, and penetration tests to identify and address potential weaknesses.
  • Incident Response: We maintain a data breach response plan and will notify affected users and relevant authorities promptly in the event of a security incident, as required by applicable law.
  • Secure Development Practices: Our development team follows secure coding standards and conducts regular code reviews to minimize security vulnerabilities in our software.

8. Your Privacy Rights

Depending on your state of residence, you may have specific rights regarding your personal information. Costa Vida is committed to honoring these rights in accordance with applicable United States law.

8.1 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the following rights:

Right Description
Right to Know You may request that we disclose what personal information we have collected, used, disclosed, or sold about you over the past 12 months.
Right to Delete You may request that we delete your personal information, subject to certain exceptions (e.g., where we need the information to complete a transaction or comply with a legal obligation).
Right to Correct You may request that we correct inaccurate personal information we hold about you.
Right to Opt-Out of Sale/Sharing You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. Costa Vida does not sell personal information for monetary value; however, certain data sharing with advertising partners may constitute "sharing" under the CPRA.
Right to Limit Use of Sensitive Personal Information You have the right to limit our use and disclosure of your sensitive personal information to what is necessary to perform the services you request.
Right to Non-Discrimination We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different prices, service levels, or quality of goods because you exercised your privacy rights.
Right to Data Portability You may request a copy of your personal information in a portable, readily usable format that allows you to transmit the data to another entity.

8.2 Rights for All U.S. Residents

Regardless of your state, you have the following general rights:

  • Right to Access: You may request a copy of the personal information we hold about you.
  • Right to Correction: You may request corrections to inaccurate or incomplete personal information.
  • Right to Opt-Out of Marketing: You may unsubscribe from our marketing emails at any time by clicking the "Unsubscribe" link in any marketing email or by contacting us directly.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

8.3 How to Exercise Your Rights

To exercise any of your privacy rights, please contact us using the following methods:

We will acknowledge your request within 10 business days and respond substantively within 45 days of receipt. We may extend this period by an additional 45 days where reasonably necessary, and we will notify you of any such extension. We may ask you to verify your identity before processing your request to prevent unauthorized access to your data.

You may designate an authorized agent to submit requests on your behalf. The authorized agent must provide written authorization signed by you, and we may verify your identity directly.


9. Cookie Usage

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, personalize content, and deliver targeted advertising. Cookies are small text files placed on your device when you visit our website.

9.1 Types of Cookies We Use

  • Essential Cookies: Necessary for the website to function properly. Without these cookies, certain features (such as the shopping cart or account login) would not work. These cannot be disabled.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous usage data (e.g., pages visited, time on site, error messages).
  • Functional Cookies: Allow our website to remember your preferences (e.g., language, region, login status) for a more personalized experience.
  • Marketing and Advertising Cookies: Used to deliver relevant advertisements to you based on your browsing behavior, both on our website and on third-party platforms.
  • Third-Party Cookies: Placed by third-party services integrated into our website (e.g., Google Analytics, Facebook Pixel, social media sharing buttons).

9.2 Managing Your Cookie Preferences

You can control and manage cookies through your browser settings. Most browsers allow you to block or delete cookies. However, please note that disabling certain cookies may affect the functionality of our website. You can also opt out of interest-based advertising through the Digital Advertising Alliance's opt-out tool at www.aboutads.info or the Network Advertising Initiative at www.networkadvertising.org.

For California residents, you may exercise your right to opt out of the sharing of your personal information through cookies for cross-context behavioral advertising by contacting us at [email protected].


10. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, resolve disputes, enforce our agreements, and support our business operations. The following general retention guidelines apply:

Category of Data Retention Period
Account information (name, email, contact details) Duration of account plus 3 years after account closure
Order and transaction records 7 years (for tax and accounting compliance)
Payment processing records 7 years (as required by financial regulations)
Customer service communications 3 years from the date of the interaction
Marketing and communication preferences Until you opt out, plus 1 year for audit purposes
Website usage and analytics data 26 months (anonymized after initial processing)
Cookies and tracking data As specified in each cookie (typically 30 days to 2 years)
Legal and compliance records As required by applicable law (typically 7 years)

Upon expiration of the applicable retention period, we will securely delete or anonymize your personal information. Where deletion is not immediately possible (e.g., because data is stored in backup archives), we will isolate the data from further processing until deletion is feasible.


11. Children's Privacy

Our website and services are intended for individuals who are 18 years of age or older. We do not knowingly collect, solicit, or process personal information from children under the age of 13 as defined under the Children's Online Privacy Protection Act (COPPA), or from minors under 18 years of age.

If you are under 18 years of age, please do not use our website, create an account, or submit any personal information to us. If you are a parent or guardian and believe that your child under 18 has provided personal information to us without your consent, please contact us immediately at [email protected]. We will take prompt steps to investigate and, if confirmed, delete the relevant information from our records.

We do not intentionally direct marketing communications to individuals under 18 years of age. Our cookie and advertising practices are configured to exclude targeting of minors to the extent technically feasible.


12. International Data Transfers

Costa Vida is based in the United States and primarily processes personal data within the United States. However, some of our third-party service providers, including analytics platforms, cloud hosting services, and email marketing tools, may operate in or transfer data to jurisdictions outside the United States.

If your personal information is transferred to, stored in, or processed in a jurisdiction other than your own, we will ensure that appropriate safeguards are in place to protect your information consistent with the requirements of applicable law. Such safeguards may include:

  • Standard contractual clauses approved by relevant data protection authorities
  • Vendor certification under recognized privacy frameworks
  • Binding corporate rules or intragroup data transfer agreements
  • Your explicit consent to the transfer

By using our website and services, you acknowledge that your personal information may be transferred to and processed in the United States or other countries, which may have different data protection laws than your country of residence. We are committed to ensuring your information remains protected regardless of where it is processed.


13. Third-Party Links and Services

Our website may contain links to third-party websites, social media platforms, delivery services, or other external resources that are not operated or controlled by Costa Vida. This Privacy Policy does not apply to those third-party websites or services. We strongly encourage you to review the privacy policies of any third-party platforms you visit through links on our website.

Costa Vida is not responsible for the privacy practices, content, or data handling of any third-party websites or services. The inclusion of a link on our website does not imply endorsement of the linked site's privacy practices.


14. Do Not Track Signals

Some web browsers allow users to send "Do Not Track" (DNT) signals to websites to request that their online behavior not be tracked. Currently, our website does not respond to DNT browser signals, as there is no industry-standard interpretation of what such signals require. However, you may opt out of certain tracking activities through our cookie management options and the opt-out links described in Section 9.

California residents may also request information about whether we disclose personal information to third parties for their direct marketing purposes. Costa Vida does not share personal information with third parties for their own direct marketing purposes without your consent.


15. Changes to This Privacy Policy

We reserve the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our practices, technologies, legal requirements, or for any other reason. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Privacy Policy
  • Post the revised policy on our website at vida-costas.world
  • Where required by law or where changes are significant, notify you by email or through a prominent notice on our website

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our website or services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you disagree with any changes, please discontinue use of our services and contact us to request deletion of your personal data.


16. Filing a Complaint with a Data Protection Authority

If you believe that Costa Vida has violated your privacy rights or applicable privacy law, we encourage you to first contact us directly so that we can address your concern. You may contact our privacy team at [email protected].

If you are a California resident and believe your CCPA/CPRA rights have been violated, you may file a complaint with the following authority:

You may also file a complaint with the Federal Trade Commission (FTC) if you believe that unfair or deceptive practices have affected you:

For residents of other states with specific privacy legislation (including Virginia, Colorado, Connecticut, Utah, Texas, and others), you may be entitled to file complaints with your state's attorney general or applicable regulatory authority. We recommend consulting your state's official government website for specific guidance.


17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us. We are committed to addressing all privacy-related inquiries promptly and transparently.

When submitting a privacy inquiry, please include the following information to help us respond efficiently:

  • Your full name
  • Your email address or other contact information
  • A clear description of your question, concern, or request
  • Your state of residence (if applicable, for state-specific rights requests)
  • Any relevant account or order information (if applicable)

We take all privacy inquiries seriously and will respond to your request within the timeframes required by applicable law. For California residents submitting CCPA/CPRA requests, we will respond within 45 days, with the possibility of a 45-day extension as described in Section 8.3.


This Privacy Policy was last updated on March 20, 2026 and is effective as of that date. © 2026 Costa Vida. All rights reserved. | vida-costas.world